VOID MANTICORE
G1055APT / State-SponsoredIranActive
Also known as: COBALT MYSTIQUE · Handala Hack · Homeland Justice · Karma · Karmabelow80 · BANISHED KITTEN · Red Sandstorm
Overview
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.
Campaigns — 1
HomeLand Justice
ended2021-05 → 2022-09
Source: MITRE C0038
T1113Screen CaptureCollection
T1110.001Password GuessingCredential Access
T1119Automated CollectionCollection
T1561.001Disk Content WipeImpact
T1486Data Encrypted for ImpactImpact
T1566PhishingInitial Access
T1589Gather Victim Identity InformationReconnaissance
T1657Financial TheftImpact
T1102
Web Service
Command and Control
T1059.001PowerShellExecution
T1047Windows Management InstrumentationExecution
T1484.001Group Policy ModificationDefense Impairment
T1564.003Hidden WindowStealth
T1583.001DomainsResource Development
T1123Audio CaptureCollection
T1190Exploit Public-Facing ApplicationInitial Access
T1114.002Remote Email CollectionCollection
T1074Data StagedCollection
T1078.002Domain AccountsStealth
T1027.015CompressionStealth
T1684.001ImpersonationStealth
T1036.005Match Legitimate Resource Name or LocationStealth
T1679Selective ExclusionStealth
T1087.002Domain AccountDiscovery
T1588.001MalwareResource Development
T1490Inhibit System RecoveryImpact
T1072Software Deployment ToolsExecution
T1003.001LSASS MemoryCredential Access
T1651Cloud Administration CommandExecution
T1583.003Virtual Private ServerResource Development
T1583.006Web ServicesResource Development
T1686.003Windows Host FirewallDefense Impairment
T1552.002Credentials in RegistryCredential Access
T1213.002SharepointCollection
T1219.002Remote Desktop SoftwareCommand and Control
T1595.002Vulnerability ScanningReconnaissance
T1561.002Disk Structure WipeImpact
T1583.004ServerResource Development
T1105Ingress Tool TransferCommand and Control
T1082System Information DiscoveryDiscovery
T1078.004Cloud AccountsStealth
T1133External Remote ServicesPersistence
T1588.002ToolResource Development
T1547.001Registry Run Keys / Startup FolderPersistence
T1204.002Malicious FileExecution
T1005Data from Local SystemCollection
T1098Account ManipulationPersistence
T1125Video CaptureCollection
T1572Protocol TunnelingCommand and Control
T1587.001MalwareResource Development